VDB

ALPINE-CVE-2024-32002

ALPINE-CVE-2024-32002 PUBLISHED CVSS 9 CRITICAL

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

Risk Scores

CVSS 3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.19git0, 1.6.0.4-r1, 1.6.1-r0
Alpine:v3.24git2.40.0
Alpine:v3.21git1.9.1-r0, 1.9.0-r0, 1.8.5.4-r0
Alpine:v3.20git2.29.0-r0, 2.21.0-r2, 2.8.0-r0
Alpine:v3.17git1.6.1.3-r1, 1.6.2.1-r0, 1.6.2.3-r0
Alpine:v3.23git1.7.11.1-r0, 1.7.11.1-r1, 1.7.11.2-r0
Alpine:v3.18git2.40.0, 2.9.3-r0, 0
Alpine:v3.22git2.28.0-r0, 2.23.0-r0, 2.3.6-r1

Timeline

  • May 14, 2024 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›